The world of web development is facing a new wave of cyber threats. Hackers have launched a large-scale campaign to breach websites based on the popular content management system WordPress. Tens of millions of resources are under attack, as their owners failed or were unable to update their software in time.
Last week, CMS developers released emergency patches to fix two critical security gaps. The situation was so serious that the WordPress team activated a mechanism for forced automatic updates for all sites where it is technically possible.
Scale of the threat and reality of attacks
Despite the measures taken, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have already recorded active hacker attacks on sites that have not yet received the fix. The statistics are alarming: system versions installed on more than 400 million resources worldwide are at risk.
Although some of them have already received an auto-update, cybersecurity consultant Daniel Card estimates the share of vulnerable sites to be around 15%. On a global scale, this amounts to about 90 million potentially vulnerable web resources.
WP2Shell Vulnerability: Full Control Over the Server
One of the critical errors was discovered by researcher Adam Cue from Searchlight Cyber. He named it WP2Shell. In combination with another bug, this vulnerability allows attackers to gain full remote control over the server and site management.
This means that hackers can not only steal data but also completely seize the infrastructure of the resource, use it for further attacks, or blackmail the owner.
Who is safe and who is in the danger zone
Experts note that several factors are currently countering the more severe consequences of the attacks. Representatives of Automattic — the company supporting the project — reported that all sites on their own hosting, including WordPress.com, Pressable, and WPVIP, were protected even before the official release of the public patch.
Other owners of self-hosted sites are in the danger zone. They are strongly advised to check the system version and update it manually as soon as possible to avoid being hacked.